CVE-2018-25100: Medium severity Mojolicious Mojo::UserAgent::CookieJar vulnerability
Published Mar 24, 2024
·Updated
The Mojolicious module before 7.66 for Perl may leak cookies in certain situations related to multiple similar cookies for the same domain. This affects Mojo::UserAgent::CookieJar.
Affected Software
1 affected component
Mojolicious Mojo::UserAgent::CookieJar<7.66
Event History
Mar 24, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·01:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-25100?
CVE-2018-25100 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2018-25100?
To fix CVE-2018-25100, you should upgrade the Mojolicious module to version 7.66 or later.
3
What software is affected by CVE-2018-25100?
CVE-2018-25100 affects the Mojolicious module for Perl, specifically the Mojo::UserAgent::CookieJar component.
4
What type of vulnerability is CVE-2018-25100?
CVE-2018-25100 is a cookie leak vulnerability that can expose multiple similar cookies for the same domain.
5
Can CVE-2018-25100 lead to security risks?
Yes, CVE-2018-25100 can lead to security risks by potentially exposing sensitive cookie data to unauthorized parties.